When is it advisable to use https with tailscale?

Tailscale is built on a VPN and all VPN's are only as strong as their weakest endpoint. So Paul is absolutely correct in what he says. If you have a Tailscale endpoint on a device that is then compromised through some other means, your entire Tailscale network is potentially compromised.

When working in commercial, high-value or highly sensitive environments, you should ALWAYS be using encrypted links internally as well as externally. And indeed, partitioning networks to prevent attackers from being able to move between segments to further reduce risk.

Obviously though, you should make your own risk-based decision as to whether you really need to do this or not.